#1109025 firmware-b43-installer: firmware download fails due to broken upstream URL and checksum mismatch

#1109025#5
Date:
2025-07-09 19:37:06 UTC
From:
To:
Dear Maintainer,

When attempting to install the package `firmware-b43-installer` on Debian 13
"Trixie" (testing), the installation fails due to a checksum mismatch of the
downloaded Broadcom firmware:

broadcom-wl-6.30.163.46.tar.bz2: checksum mismatch
sha512sum: WARNING: 1 computed checksum did NOT match
firmware-b43-installer.postinst: Downloaded firmware did not match known SHA512
checksum, aborting.
dpkg: error processing package firmware-b43-installer (--configure)

This happens because the URL used to fetch the firmware redirects to a
suspended hosting page (`cgi-sys/suspendedpage.cgi`), meaning the downloaded
content is not valid, resulting in a broken installation.

Steps to reproduce (on Debian Trixie):
1. `sudo apt install firmware-b43-installer`
2. Observe download and checksum failure.
3. Package fails to configure; Wi-Fi support is broken.

Expected result:
- The installer should download a valid firmware file or handle the missing
source gracefully.
- Systems relying on Broadcom Wi-Fi should not be left without a working
driver.

This violates Debian Policy §4.9: maintainer scripts should be robust and not
fail in this way.

Thank you for your work maintaining Debian packages.

Best regards,
catmaster
(Reporting from Debian Bookworm, but the issue occurs on Trixie)

#1109025#10
Date:
2025-07-10 07:41:27 UTC
From:
To:
control: tags -1 + confirmed patch

  I disagree that this is a policy violation; the cause of error is
clearly reported. Not sure how the script could be more resilient when
a remote resource has disappeared:

  I did find a mirror of the files on GitHub at
https://github.com/minios-linux/b43-firmware/releases with matching
SHA512 sums. I think an easy fix would be to point the install script
to GitHub, which is probably more reliable long-term.

Mathias

#1109025#17
Date:
2025-07-10 07:53:10 UTC
From:
To:
Mathias Gibbens <gibmat@debian.org> writes:

I tend to agree -- the package is in contrib, which I think are entitled
to do "bad" things like downloading executables from the Internet and
use them?

Are these blobs distributable?  I suppose not.  Maybe having a list of
known URLs and have the client try all of them would be more reliable.
It may become a cat and mouse chase.

/Simon

#1109025#22
Date:
2025-07-10 09:33:24 UTC
From:
To:
  Correct; the package source itself is DFSG, but it depends on non-
free binary blobs which is why it's in contrib.

  I also have doubts about redistributabilty of the binary firmware
itself. I couldn't find any license/readme either on the GitHub mirror
or using the Wayback Machine to look at the original download site. In
theory requiring the user to download each time via the postinst script
works around it, at least from Debian's end, but I don't know about the
site(s) that are actually hosting the firmware.

  This package has been orphaned for over a decade now, which is
certainly less than ideal.

Mathias

#1109025#27
Date:
2025-07-14 02:28:38 UTC
From:
To:
This bug report has been tagged "patch" but there seems to be no patch available.
#1109025#32
Date:
2025-07-14 05:50:01 UTC
From:
To:
  I tagged with patch because I think the fix is just a one line change
in the postinst script:

  There's concern about hosting of the firmware files, but that problem
pre-dates this issue where the website referenced by the script has
disappeared.

  I guess I'll go ahead and prepare an unblock pre-approval request; if
the RT approves I'll then do a QA upload of this package.

Mathias

#1109025#37
Date:
2025-07-14 06:06:51 UTC
From:
To:
There still seem to be machines in active use that need that firmware, so an upgrade would be welcome.
Ofc the firmware itself is in a grey area, but I don't know of any other way to get it.

#1109025#42
Date:
2025-07-16 17:14:44 UTC
From:
To:
tag 1109244 confirmed moreinfo
thanks

Hi,


Please go ahead. Remove the moreinfo tag once the upload has happened.

Maybe the mechanism to determine the URL could be changed after the
trixie release. Just a hint/idea: have the package look for the URL at a
group maintained URL (on salsa or something similar) in a signed file
such that the URL can be uploaded out of band, but still a trust path
exists. I recall extrepo works that way.

Paul

#1109025#47
Date:
2025-07-17 07:18:55 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
b43-fwcutter, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1109025@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Mathias Gibbens <gibmat@debian.org> (supplier of updated b43-fwcutter package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 14 Jul 2025 05:52:41 +0000
Source: b43-fwcutter
Architecture: source
Version: 1:019-14
Distribution: unstable
Urgency: medium
Maintainer: Debian QA Group <packages@qa.debian.org>
Changed-By: Mathias Gibbens <gibmat@debian.org>
Closes: 1109025
Changes:
 b43-fwcutter (1:019-14) unstable; urgency=medium
 .
   * QA upload.
   * Update remote site where firmware can be fetched (Closes: #1109025)
Checksums-Sha1:
 f8d1b98aca8f10cd2d9feeb224d15df45c7b20f0 2127 b43-fwcutter_019-14.dsc
 64198fd2885b0eb0f8968ce3dc2037545b67f065 46769 b43-fwcutter_019.orig.tar.bz2
 0c05033aa906af2252c8a911443f74dafc417db8 21356 b43-fwcutter_019-14.debian.tar.xz
 f8e20f856800e0c680f9b74faca68d93ab0cd478 6511 b43-fwcutter_019-14_amd64.buildinfo
Checksums-Sha256:
 5bf2f7803f564cd62e960994901b9937e1cd8ec515b7cc0b09f9a0123ea58059 2127 b43-fwcutter_019-14.dsc
 d6ea85310df6ae08e7f7e46d8b975e17fc867145ee249307413cfbe15d7121ce 46769 b43-fwcutter_019.orig.tar.bz2
 be36d9b6bf6a647b6668f8f3589c672d0cbc73c647f1555a03996d54d768a0e7 21356 b43-fwcutter_019-14.debian.tar.xz
 dbaeb5e742c285ff2e0fcd45f669e34a9a586f8790f371662d3b42ee65773eb0 6511 b43-fwcutter_019-14_amd64.buildinfo
Files:
 cfc14af0897c5b9b2f7abf963f68524b 2127 contrib/utils optional b43-fwcutter_019-14.dsc
 19d1f4226a625756726bdf7ed5dc2a0a 46769 contrib/utils optional b43-fwcutter_019.orig.tar.bz2
 b50f2aa5e0dd1540d60d13bcd0885ca6 21356 contrib/utils optional b43-fwcutter_019-14.debian.tar.xz
 722cfcd24aaaba0cfd455cf22bd33a87 6511 contrib/utils optional b43-fwcutter_019-14_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJGBAEBCgAwFiEE1Bp60H32xfynSJ8cKe7i1uz0QvkFAmh4oGASHGdpYm1hdEBk
ZWJpYW4ub3JnAAoJECnu4tbs9EL51iAP/1gtcAwN3ccxj/gHZwlka4Rdok3u/ehT
5RM6v0ympJhE8HRL+8y2mG0YlL3uyz3XJXL3s9gHsoEBjZOBeASGrMGXkynYqMOi
WtHqYKL4GhAIABZkerfC01BKFaz6gsGHosXQ+kLmfZ6XYTiRrocBoX+sIVDvOiqM
ChsbWTSTffISD9calTYiKH6wpA6lSUCQhS+MYgpUiCP6fuqa6UNsnhRVH/JW+SFH
LpE/I2MwY8ctt3FudYRMKUuX9agBAbfj3FwhcA0cXhWX5VhWuZbEhphTAL2cxZki
eCXeqgsBTNeMUQLj6Eo+UGbtkJT/nC2bj2b8LWD42LPg0K8sHBTw4mJ4V/e6+4UG
2X2PwYiTz+/YUIdHtF/hhCez8thU4cGipEjvX4sdNxJ0HHwFlbK+W9ES9eQ+dT/j
ZmDq4N4AwgTRaNxKZQ58EIeAxhwwkpSde2qUd/88pydeg4DPYALNuz9kZIQpXGoL
ZNRZXp2KmbKEao9KUXR4rZrk1oAnhh0PCmKkyDDMKwzA8jS1h6y5x9qEnn/qsF6g
zIbN4b7K/k6k0gk6XHzqoKNKo4bXkgaa6Ov5l1GXaTSU85KFfkgvc/i5tZChAxYy
FvyKQGvxwWGtwNKpetwe5wB0eLBzZINkRvSCof6Das2fNjqUqyVvcm5QyytPvAmE
54hap5EBYFPh
=4l14
-----END PGP SIGNATURE-----

#1109025#52
Date:
2025-07-30 18:17:09 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
b43-fwcutter, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1109025@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Mathias Gibbens <gibmat@debian.org> (supplier of updated b43-fwcutter package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 23 Jul 2025 11:05:22 +0000
Source: b43-fwcutter
Architecture: source
Version: 1:019-8+deb12u1
Distribution: bookworm
Urgency: medium
Maintainer: Debian QA Group <packages@qa.debian.org>
Changed-By: Mathias Gibbens <gibmat@debian.org>
Closes: 1109025
Changes:
 b43-fwcutter (1:019-8+deb12u1) bookworm; urgency=medium
 .
   * QA upload.
   * Update remote site where firmware can be fetched (Closes: #1109025)
Checksums-Sha1:
 7236a54186407b54bdaa83042380a547a5920f5c 2155 b43-fwcutter_019-8+deb12u1.dsc
 64198fd2885b0eb0f8968ce3dc2037545b67f065 46769 b43-fwcutter_019.orig.tar.bz2
 8a4cb054178981d7e19ae1468fb52559380a1a22 20280 b43-fwcutter_019-8+deb12u1.debian.tar.xz
 e2367252d1963aac80e6d31f8bc2d54c40f96694 7154 b43-fwcutter_019-8+deb12u1_amd64.buildinfo
Checksums-Sha256:
 15b7f163c51910f42ea57d49a25832d425d33e83857101c0bbf2507c6d84628c 2155 b43-fwcutter_019-8+deb12u1.dsc
 d6ea85310df6ae08e7f7e46d8b975e17fc867145ee249307413cfbe15d7121ce 46769 b43-fwcutter_019.orig.tar.bz2
 366bb0cb30fcb246802fe6548e068f5642cd447ecc2a4b251be0d8bc9a58a430 20280 b43-fwcutter_019-8+deb12u1.debian.tar.xz
 034ab77c7381874d9da08fa17c360087bf92c75c7b3103329b1f8cc4224f0e30 7154 b43-fwcutter_019-8+deb12u1_amd64.buildinfo
Files:
 a89bf8bbab276ddebff220cfbd8d59ea 2155 contrib/utils optional b43-fwcutter_019-8+deb12u1.dsc
 19d1f4226a625756726bdf7ed5dc2a0a 46769 contrib/utils optional b43-fwcutter_019.orig.tar.bz2
 e9d8523a9eca3b61b2ab50b7bb404e36 20280 contrib/utils optional b43-fwcutter_019-8+deb12u1.debian.tar.xz
 0f94ad7fc9776b99d4990d5378f06b70 7154 contrib/utils optional b43-fwcutter_019-8+deb12u1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJGBAEBCgAwFiEE1Bp60H32xfynSJ8cKe7i1uz0QvkFAmiKMSYSHGdpYm1hdEBk
ZWJpYW4ub3JnAAoJECnu4tbs9EL5nxkP/3GAE7KvD9wgjAmmomHVkOK3wKMmMuAg
CFXywT69lY2fydhQgd5T7FazPe06i6XtztpWHK3vljzy+S5NEc4HDzcTbsGQ0e9l
NOfdFdIb72FDzNyTuRZgIWy1bbb5PjkQwrn5EnAjHoskWp03kQBex1glh2r5GV/B
3s5PWI5lr2k1hyfzABsomIr7kHLg4GZ0j1wJ/GMI9Binhi3woi9s/S6HnP7CSH+W
tSFQCWgekm0P0MV4VCpNQqltLVbgtaa2ylvJDqi1pt/CIzYwWe8mfqyRymn0TrMH
4vZu92J5ngvr7yXWItVl8zBb8RjqRbQgfg184snvi+M47hJDPZkkysuefbQcT/wP
n1HEmwKeqWOaH0/ZN/PsYMphIJMrsMvDPCz1uPtt6pWG1E2l1foFNGxfqKZOo6dw
BXKc0dOuFZwStaYvOlUiK7F0W67l7Hsp2OufLUt6Ng5NyxZw/s/Q5nF+UAWCkVve
PNPVsoBiKUs9Au3IWZBBHmwUBNKcy4/L2SnAweOpIydvy5JoA7Y4xlxZ4CHDI3lb
IEn4qah4urv91ksJn6xk4ElRE9kzXTRX3uW4iuNQ31L5uEp1M2VTf+KGspjkFyS/
cn2J/O6LzqVaDdnoTEwHhSA/oZCbFnv3Ruh5/45eRFSAXDua1Xl1nsIk8T17Rkoo
DgHLcqARxk/D
=JweL
-----END PGP SIGNATURE-----